NetworkPolicy provides fine-grained control over what network destinations a sandbox can reach. It operates at two layers: kernel-level IP filtering via iptables and application-level domain filtering via the per-namespace TCP proxy.
NetworkPolicy model
Domain-based rules
Domain entries inallow_out and deny_out are matched against the TLS SNI field (HTTPS) or HTTP Host header (HTTP).
Exact match
Wildcard subdomains
Regex patterns
Prefix the entry with~ to use a regex:
IP and CIDR rules
IP and CIDR entries bypass the domain proxy and are applied directly asiptables rules in the kernel — zero userspace overhead.
ALL_TRAFFIC is equivalent to "0.0.0.0/0".
Any
allow_out entry turns egress into a whitelist. As soon as allow_out is
non-empty — whether it lists domains, IPs, or CIDRs — the sandbox may reach only
the listed destinations; everything else is denied. The explicit
deny_out=[ALL_TRAFFIC] in the example above is therefore optional (it is implied by
the allowlist), though harmless to include. A sandbox created with no network
policy is unrestricted — the allowlist applies only when you opt in with allow_out.Egress enforcement is IPv4. Declaw sandboxes route IPv4 only — IPv6 egress is
disabled (dropped at the kernel), so a sandbox cannot send IPv6 traffic regardless
of policy. Virtually every public endpoint is reachable over IPv4, so this is
transparent in normal use, and it guarantees an
allow_out allowlist cannot be
bypassed over IPv6. IPv6-only destinations are not currently supported.Priority rules
Allow rules always take precedence over deny rules, regardless of the order they are listed.Metadata service blocking
Cloud instance-metadata and credential endpoints are always blocked in every sandbox, regardless of the network policy (or whether one is set). This prevents SSRF attacks where agent code could steal the worker’s cloud credentials. The blocked endpoints are:169.254.169.254— AWS/Azure IMDS and GCP metadata (metadata.google.internalresolves here)169.254.170.2— AWS ECS/Fargate task metadata + credentials169.254.170.23— AWS EKS Pod Identity- all IPv6 metadata endpoints (IPv6 egress is disabled entirely — see above)
DNS resolution under an allowlist
DNS keeps working whenever you set an egress allowlist — you do not need to add your resolver toallow_out manually:
- Domain allowlists: Declaw runs a per-sandbox resolver that resolves your allowed domains and permits the resulting IPs automatically (this also handles CDN IP rotation, so a domain whose IPs change stays reachable).
- IP/CIDR allowlists: outbound DNS (UDP port 53) to Declaw’s resolvers is
permitted so
gethostbyname()continues to resolve. DNS is scoped to those resolvers — a sandbox cannot send UDP/53 to an arbitrary host. To use a custom resolver, add its IP toallow_out.
Under an IP/CIDR allowlist, resolving a name does not grant access to its IP — you
can look up any hostname, but you can only connect to the IPs you listed. To allow a
service by name, add it as a domain entry in
allow_out: domain entries
resolve the name and permit the resolved IPs, whereas a raw IP allowlist does not.How the TCP proxy works
The proxy runs in the host network namespace for the sandbox’s network namespace. All TCP traffic from the VM is redirected to the proxy viaiptables REDIRECT rules applied to the per-sandbox veth interface.
For HTTPS connections, the proxy peeks at the TLS ClientHello (without decrypting) to extract the SNI hostname. For HTTP connections, it reads the first line of the request to find the Host header.
If the hostname is in the allowlist and no body scanning is required, the proxy connects to the real destination and forwards the TCP stream directly without any TLS interception. This means there is no TLS overhead for pure network policies.
Combine with SecurityPolicy for full control
NetworkPolicy as a field inside SecurityPolicy integrates with PII scanning and audit logging:
- iptables drops all non-DNS outbound traffic by default
- TCP proxy intercepts connections to
*.openai.comand*.anthropic.com - PII scanner activates TLS interception on those allowed domains
- All events are logged to the audit trail